OpenAI Codex Chains HTTP/2 DoS Attacks Autonomously

🟠 High | Source: The Register — Security OpenAI’s Codex AI agent independently discovered and chained together multiple decade-old HTTP/2 denial-of-service techniques to bring down web servers within seconds, creating what researchers are calling an HTTP/2 bomb. This demonstrates that AI coding agents can autonomously rediscover and combine legacy attack methods into novel, highly effective exploits without human guidance. The incident raises significant concerns about the offensive security capabilities of large language model-based agents operating with minimal oversight. ...

4 June 2026 Â· ZX Cloud Security

HTTP/2 Bomb DoS Flaw Hits NGINX, Apache, IIS & Envoy

🟠 High | Source: The Hacker News A newly discovered vulnerability dubbed ‘HTTP/2 Bomb’ allows attackers to remotely crash major web servers — including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora — without authentication. The flaw exploits default HTTP/2 configurations, meaning most deployments are vulnerable out of the box. Because it affects such a broad range of widely used infrastructure, the potential impact is significant across cloud and on-premises environments alike. ...

3 June 2026 Â· ZX Cloud Security